Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 182

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
How to find the log in page in q2amarket.com
Scrolling Notice Board
China eases IPO rules for firms developing reusable rockets
Psychology expert: The most emotionally intelligent couples do 3 things differently from everyone else
Are dividends better for investors than stock buybacks? It all depends
Oracle shares on pace for worst quarter since 2001 as new CEOs face concerns about AI build-out
Here’s where you can still snag 4% yields on idle cash
Over 300,000 student loan borrowers were denied a new repayment plan, court filing shows — here's why
Russian drones, missiles pound Ukraine ahead of Trump-Zelenskyy meeting
Forget Gen Z and Millennials — the over-50s ‘Silver Spenders’ are powering investment opportunities, including these stocks